DocumentCode :
3126554
Title :
An Access Control System for Web Service Compositions
Author :
Srivatsa, Mudhakar ; Iyengar, Arun ; Mikalsen, Thomas ; Rouvellou, Isabelle ; Yin, Jian
Author_Institution :
Georgia Inst. of Technol., Atlanta
fYear :
2007
fDate :
9-13 July 2007
Firstpage :
1
Lastpage :
8
Abstract :
Service composition has emerged as a fundamental technique for developing Web applications. Multiple services, often from different organizations or trust domains, may be dynamically composed to satisfy a user´s request. Access control in the presence of service compositions is a challenging security problem. In this paper, we present an access control model and techniques for specifying and enforcing access control rules on Web service compositions. A key advantage of our approach is that past histories of service invocations can be used to make access control decisions. Our approach allows role hierarchies and separation of duty constraints. Access controls rules may be parameterized by one or more arguments. We have implemented our access control model via a declarative policy specification language which uses pure-past linear temporal logic (PPLTL). We describe an implementation of our approach using a supply chain management (SCM) application. Our experiments show that our approach can enforce expressive and flexible access control policies while incurring reasonable performance overhead on the application.
Keywords :
Web services; authorisation; supply chain management; temporal logic; Web service compositions; access control system; pure-past linear temporal logic; security problem; service invocations; supply chain management; Access control; Databases; Educational institutions; History; Logic; Manufacturing; Security; Specification languages; Supply chain management; Web services;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Web Services, 2007. ICWS 2007. IEEE International Conference on
Conference_Location :
Salt Lake City, UT
Print_ISBN :
0-7695-2924-0
Type :
conf
DOI :
10.1109/ICWS.2007.31
Filename :
4279576
Link To Document :
بازگشت